About the Organization (Anonymized*)
This insurance holding firm oversees a portfolio of insurance and financial services entities that manage a significant amount of capital on behalf of investors and policyholders. As partnerships with larger, publicly traded organizations expanded, leadership needed a security model that would stand up to scrutiny from those partners, regulators and auditors.
The Challenge
Insurance and financial services firms sit at the top of attackers’ target lists because they manage a significant amount of capital, process and store sensitive financial data, and connect into the broader financial ecosystem.
A single compromised user or device can put the entire organization, and its partners, at risk. The security framework built to address this is known as Zero Trust.
What is Zero Trust? NIST defines Zero Trust as a security framework built on a single premise: no user, device, or session is trusted by default regardless of whether it sits inside or outside the network perimeter. Every access request is authenticated and authorized before a connection is established.
At the onset of their engagement with Macro, the firm faced four converging pressures:
- Larger, publicly traded partners operate under Zero Trust principles and expect the same in return.
- Sophisticated attacks across the industry increasingly bypassed EDR/MDR by weaponizing legitimate IT tools.
- Pressure increased from auditors, insurers, and regulators not only to assert that access was controlled but to prove it.
Zero Trust was the right architectural answer. But getting there required more than turning on a feature.
The Solution
Macro designed and implemented a layered Zero Trust framework. No user, device, or location is trusted by default, and access is granted only after multiple conditions are verified.
1. Application allowlisting and endpoint hardening
Macro deployed application allow listing across all endpoints — only known, approved applications can execute. All other applications are blocked, whether the installer arrived through a download, USB stick, or social engineering attempt.
This closes a fast-growing attack pattern: threat actors weaponizing legitimate remote access and admin tools that EDR/MDR don’t flag by default. Now, trusted-by-reputation no longer means safe-to-run.
2. Device-based conditional access
Authentication alone is no longer enough. Before a user can reach company resources, the device must meet a defined security baseline:
- Registered with Entra ID (Azure AD)
- Managed by Microsoft Intune
- Encrypted with BitLocker
- Run approved endpoint protection and be current on critical security patches
Non-compliant devices or devices not enrolled in Intune are blocked from accessing the company’s resources, which means a stolen credential alone isn’t enough to get in.
3. Geographic access controls with an automated travel workflow
The firm now blocks authentication from outside the United States by default which eliminates a significant volume of credential-stuffing and account-takeover attempts originating from foreign IPs.
For employees with legitimate travel needs, Macro built an automated workflow: the employee submits a request, HR approves based on tax and compliance requirements, and the system temporarily adds them to the appropriate exclusion group — then revokes access upon their return date. A manual back-and-forth became a governed, auditable process.
4. Security awareness training as a baseline
Zero Trust limits the damage a user mistake can cause — but it can’t stop the mistake from happening. Macro layered ongoing security awareness training and phishing simulations into the program, so technical controls are reinforced by users who can spot social engineering before it becomes an incident.
Zero Trust isn’t one tool you switch on. It’s a set of decisions — about who connects, from where, on what device, and to what. Every layer has to be designed for the way the business actually operates, or it just gets in people’s way.
— Brendan Thompson, Director of AI, Architecture and Engineering
The Results
Attacks neutralized before they execute
Application allowlisting blocks weaponized IT tools and unapproved software from running. Entire categories of attacks are eliminated without relying on users to identify them in the moment.
Alignment with partner and regulatory expectations
The firm’s Zero Trust posture now matches what its larger, publicly traded partners require — removing friction in those relationships and supporting audit readiness.
Controlled travel without security gaps
Employees can work from approved locations abroad without weakening the firm’s default security posture or creating a manual exception process that gets bypassed under pressure.
A defensible security posture
Every access decision is now governed by policy, logged for auditing purposes, and reviewable. When auditors, insurers, or partners ask how access is controlled, the documentation matches what the environment actually does.
Stop trusting by default. Start verifying by design. If your firm needs a Zero Trust architecture built around how your business actually operates, we can help.
*We respect privacy requests from our clients.

